Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation of HTTP headers, a remote attacker is able to elevate their privilege by tunneling HTTP requests, allowing them to execute HTTP requests on the backend server that hosts the repository application. The fixed versions are August 2023 Patch 2, May 2023 Patch 6, February 2023 Patch 10, November 2022 Patch 12, August 2022 Patch 14, May 2022 Patch 16, February 2022 Patch 15, and November 2021 Patch 17. NOTE: this issue exists because of an incomplete fix for CVE-2023-41265.
| Software | From | Fixed in |
|---|---|---|
| qlik / qlik_sense | august_2022-patch_12 | august_2022-patch_12.x |
| qlik / qlik_sense | august_2022-patch_11 | august_2022-patch_11.x |
| qlik / qlik_sense | august_2022-patch_10 | august_2022-patch_10.x |
| qlik / qlik_sense | august_2022-patch_9 | august_2022-patch_9.x |
| qlik / qlik_sense | august_2022-patch_8 | august_2022-patch_8.x |
| qlik / qlik_sense | august_2022-patch_7 | august_2022-patch_7.x |
| qlik / qlik_sense | august_2022-patch_6 | august_2022-patch_6.x |
| qlik / qlik_sense | august_2022-patch_5 | august_2022-patch_5.x |
| qlik / qlik_sense | august_2022-patch_4 | august_2022-patch_4.x |
| qlik / qlik_sense | august_2022-patch_3 | august_2022-patch_3.x |
| qlik / qlik_sense | august_2022-patch_2 | august_2022-patch_2.x |
| qlik / qlik_sense | august_2022-patch_1 | august_2022-patch_1.x |
| qlik / qlik_sense | august_2022 | august_2022.x |
| qlik / qlik_sense | november_2022-patch_10 | november_2022-patch_10.x |
| qlik / qlik_sense | november_2022-patch_9 | november_2022-patch_9.x |
| qlik / qlik_sense | november_2022-patch_8 | november_2022-patch_8.x |
| qlik / qlik_sense | november_2022-patch_7 | november_2022-patch_7.x |
| qlik / qlik_sense | november_2022-patch_6 | november_2022-patch_6.x |
| qlik / qlik_sense | november_2022-patch_5 | november_2022-patch_5.x |
| qlik / qlik_sense | november_2022-patch_4 | november_2022-patch_4.x |
| qlik / qlik_sense | november_2022-patch_3 | november_2022-patch_3.x |
| qlik / qlik_sense | november_2022-patch_2 | november_2022-patch_2.x |
| qlik / qlik_sense | november_2022-patch_1 | november_2022-patch_1.x |
| qlik / qlik_sense | november_2022 | november_2022.x |
| qlik / qlik_sense | february_2023-patch_7 | february_2023-patch_7.x |
| qlik / qlik_sense | february_2023-patch_6 | february_2023-patch_6.x |
| qlik / qlik_sense | february_2023-patch_5 | february_2023-patch_5.x |
| qlik / qlik_sense | february_2023-patch_4 | february_2023-patch_4.x |
| qlik / qlik_sense | february_2023-patch_3 | february_2023-patch_3.x |
| qlik / qlik_sense | february_2023-patch_2 | february_2023-patch_2.x |
| qlik / qlik_sense | february_2023-patch_1 | february_2023-patch_1.x |
| qlik / qlik_sense | february_2023 | february_2023.x |
| qlik / qlik_sense | may_2023-patch_2 | may_2023-patch_2.x |
| qlik / qlik_sense | may_2023-patch_1 | may_2023-patch_1.x |
| qlik / qlik_sense | may_2023 | may_2023.x |
| qlik / qlik_sense | november_2021-patch_1 | november_2021-patch_1.x |
| qlik / qlik_sense | november_2021-patch_2 | november_2021-patch_2.x |
| qlik / qlik_sense | november_2021-patch_3 | november_2021-patch_3.x |
| qlik / qlik_sense | november_2021-patch_4 | november_2021-patch_4.x |
| qlik / qlik_sense | november_2021-patch_5 | november_2021-patch_5.x |
| qlik / qlik_sense | november_2021-patch_6 | november_2021-patch_6.x |
| qlik / qlik_sense | november_2021-patch_7 | november_2021-patch_7.x |
| qlik / qlik_sense | november_2021-patch_8 | november_2021-patch_8.x |
| qlik / qlik_sense | november_2021-patch_9 | november_2021-patch_9.x |
| qlik / qlik_sense | november_2021-patch_10 | november_2021-patch_10.x |
| qlik / qlik_sense | november_2021-patch_11 | november_2021-patch_11.x |
| qlik / qlik_sense | november_2021-patch_12 | november_2021-patch_12.x |
| qlik / qlik_sense | november_2021-patch_13 | november_2021-patch_13.x |
| qlik / qlik_sense | november_2021-patch_14 | november_2021-patch_14.x |
| qlik / qlik_sense | november_2021-patch_15 | november_2021-patch_15.x |
| qlik / qlik_sense | november_2021-patch_16 | november_2021-patch_16.x |
| qlik / qlik_sense | february_2022-patch_1 | february_2022-patch_1.x |
| qlik / qlik_sense | february_2022-patch_3 | february_2022-patch_3.x |
| qlik / qlik_sense | february_2022-patch_2 | february_2022-patch_2.x |
| qlik / qlik_sense | february_2022-patch_4 | february_2022-patch_4.x |
| qlik / qlik_sense | february_2022-patch_5 | february_2022-patch_5.x |
| qlik / qlik_sense | february_2022-patch_6 | february_2022-patch_6.x |
| qlik / qlik_sense | february_2022-patch_7 | february_2022-patch_7.x |
| qlik / qlik_sense | february_2022-patch_8 | february_2022-patch_8.x |
| qlik / qlik_sense | february_2022-patch_9 | february_2022-patch_9.x |
| qlik / qlik_sense | february_2022-patch_10 | february_2022-patch_10.x |
| qlik / qlik_sense | february_2022-patch_11 | february_2022-patch_11.x |
| qlik / qlik_sense | february_2022-patch_12 | february_2022-patch_12.x |
| qlik / qlik_sense | february_2022-patch_13 | february_2022-patch_13.x |
| qlik / qlik_sense | february_2022-patch_14 | february_2022-patch_14.x |
| qlik / qlik_sense | may_2022-patch_1 | may_2022-patch_1.x |
| qlik / qlik_sense | may_2022-patch_2 | may_2022-patch_2.x |
| qlik / qlik_sense | may_2022-patch_3 | may_2022-patch_3.x |
| qlik / qlik_sense | may_2022-patch_4 | may_2022-patch_4.x |
| qlik / qlik_sense | may_2022-patch_5 | may_2022-patch_5.x |
| qlik / qlik_sense | may_2022-patch_6 | may_2022-patch_6.x |
| qlik / qlik_sense | may_2022-patch_7 | may_2022-patch_7.x |
| qlik / qlik_sense | may_2022-patch_8 | may_2022-patch_8.x |
| qlik / qlik_sense | may_2022-patch_9 | may_2022-patch_9.x |
| qlik / qlik_sense | may_2022-patch_10 | may_2022-patch_10.x |
| qlik / qlik_sense | may_2022-patch_11 | may_2022-patch_11.x |
| qlik / qlik_sense | may_2022-patch_12 | may_2022-patch_12.x |
| qlik / qlik_sense | may_2022-patch_13 | may_2022-patch_13.x |
| qlik / qlik_sense | may_2022-patch_14 | may_2022-patch_14.x |
| qlik / qlik_sense | may_2022-patch_15 | may_2022-patch_15.x |
| qlik / qlik_sense | august_2022-patch_13 | august_2022-patch_13.x |
| qlik / qlik_sense | november_2022-patch_11 | november_2022-patch_11.x |
| qlik / qlik_sense | february_2023-patch_8 | february_2023-patch_8.x |
| qlik / qlik_sense | february_2023-patch_9 | february_2023-patch_9.x |
| qlik / qlik_sense | may_2023-patch_3 | may_2023-patch_3.x |
| qlik / qlik_sense | may_2023-patch_4 | may_2023-patch_4.x |
| qlik / qlik_sense | may_2023-patch_5 | may_2023-patch_5.x |
| qlik / qlik_sense | august_2023-patch_1 | august_2023-patch_1.x |
| qlik / qlik_sense | august_2023 | august_2023.x |
| qlik / qlik_sense | may_2022 | may_2022.x |
| qlik / qlik_sense | february_2022 | february_2022.x |
| qlik / qlik_sense | november_2021 | november_2021.x |